Loading...

Microsoft Purview | Insider Risk Management – Personal email triggers

Microsoft Purview | Insider Risk Management – Personal email triggers

Microsoft Purview Insider Risk Management will add two new email triggers in September 2025 to detect data exfiltration via attachments sent to personal or public email domains. These triggers can be enabled in IRM settings and will update quick policy templates without affecting existing policies. No action required. Introduction To enhance detection capabilities in Insider Risk Management (IRM), we’re adding two new email indicators as triggers for data exfiltration activities. These indicators help identify potential data leaks when users send business-sensitive attachments to personal or public email domains. This update supports stronger data protection and aligns with customer feedback requesting broader coverage of email-based risks. This message is associated with Microsoft 365 Roadmap ID 496149. When this will happen: General Availability (Worldwide, GCC, GCC High, GCC DoD): Rollout will begin in early September 2025 and is expected to complete by late September 2025. How this affects your organization:What you can do to prepare: No action is required. The new triggers will automatically become available for configuration in the IRM policy wizard. Compliance considerations: No compliance considerations identified, review as appropriate for your organization. Who is affected: Admins managing Insider Risk Management policies. What will happen: Two new email triggers will be available: Sending email with attachments to free public domains. Sending email with attachments to self (personal email). These indicators can be enabled from the IRM settings page. Sequence detections will now include these indicators as exfiltration activities. IRM quick policy templates will be updated: Email exfiltration: These two indicators will be set as default triggers and indicators. Sending email with attachments to external recipients will not be enabled by default. Data leaks: Both indicators will be added to triggers and indicators, with no changes to existing ones. Data theft by users leaving your org: Indicators will be added; existing triggers and indicators remain unchanged. Critical asset protection: Both indicators will be added to triggers and indicators, with no changes to existing ones. Existing policies created from quick templates will not be affected. Message ID: MC1147381

The post Microsoft Purview | Insider Risk Management – Personal email triggers appeared first on M365 Admin.

Published on:

Learn more
Need help with this product?

We can help you with Microsoft Purview | Insider Risk Management – Personal email triggers

If you want help implementing, troubleshooting, or improving this product, contact us and we’ll point you in the right direction.

M365 Admin
M365 Admin

by João Ferreira

Share post:

Related posts

Preparing the Windows ecosystem for next-generation code signing

Rollout schedule: Microsoft guidance is already available. October 19, 2026: Microsoft Windows Production PCA 2011 expires. End of 2026: Windo...

10 hours ago

Microsoft Viva: Viva Learning retirement of Microsoft 365 training content

Microsoft is retiring 161 Microsoft 365 training modules and selected articles from Viva Learning on September 21, 2026, removing outdated con...

10 hours ago

Improved capabilities for files with Copilot in OneDrive Web

Copilot in OneDrive Web enables users with a Microsoft 365 Copilot license to find, understand, analyze, create, and act on files using natura...

10 hours ago

Microsoft Teams: Prepare custom apps for private and shared channel compatibility

Microsoft Teams will roll out a feature by September 2026 to help admins identify custom line-of-business apps needing updates for private and...

10 hours ago

Microsoft Entra ID: Passkey support for B2B users

Microsoft Entra ID will support passkey registration and sign-in for B2B users to meet resource tenant MFA requirements, enhancing phishing re...

10 hours ago

Microsoft 365 admin center: Usage reports migrating to new domains

Microsoft 365 admin center Usage reports domains will change starting mid-August 2026, with current and new domains active in parallel for at ...

10 hours ago

Microsoft Teams: Local Pan-tilt-zoom (PTZ) controls for Microsoft Teams Rooms on Windows

Microsoft Teams Rooms on Windows will add native local Pan-Tilt-Zoom (PTZ) camera controls for compatible mechanical or optical PTZ cameras, a...

10 hours ago

New in Microsoft 365 Copilot: Self-serve Copilot Connectors

Microsoft 365 Copilot now offers self-serve connectors, allowing users to securely sync external data like Jira and Confluence with their cred...

10 hours ago

Microsoft Teams: Admin policy to automatically block identified external meeting bots from joining meetings

Microsoft Teams will introduce a new admin policy, starting August 2026, allowing automatic blocking of identified external meeting bots from ...

10 hours ago

Microsoft 365 Copilot: Personalized Copilot Suggestions Coming to Frontier

Microsoft 365 Copilot will introduce personalized AI suggestions in Copilot Chat for eligible Frontier program users starting early August 202...

10 hours ago

Newsletter

Get the latest Dynamics 365 and Power Platform content in your inbox

A curated digest of community blogs, product news, videos, and podcasts — delivered without the noise.

Weekly updates Unsubscribe anytime Fresh community picks
We use your email only for the newsletter and you can unsubscribe at any time.
By subscribing, you agree to the privacy policy.